Self-hosted assets

The public site should be inspectable from its own build output.

Fonts, images, CSS, JavaScript, icons, and other interface assets should ship from the site unless there is a specific reason to depend on a remote runtime service.

Rule#

Self-host assets by default. A remote asset is an exception that needs a reason, a disclosure decision, and a maintenance owner.

Applies to#

  • web fonts
  • JavaScript libraries
  • CSS frameworks or generated CSS
  • icons and interface images
  • downloaded product images when licensing allows local hosting
  • generated files such as search indexes, feeds, and machine-readable surfaces

Why#

Self-hosting keeps the site:

  • faster to render
  • easier to archive
  • easier to test
  • less dependent on third-party uptime
  • less exposed to third-party tracking
  • clearer about what code runs in the browser

Exceptions#

A remote dependency may be acceptable when it is the product being demonstrated, a legally required source, a live service that cannot be represented locally, or a temporary migration state.

Document the exception near the feature and disclose it where a visitor or maintainer would reasonably expect to find it.

Maintenance#

When adding an asset, answer three questions:

  • Where is the local source?
  • What license or permission allows use?
  • Does this asset cause browser-side requests outside the site?